New: Roadmaps ordered paths through our cheat sheets and flashcards, so you always know what to study next.
Explore themSee what's new on GitHubFrom your first authorized scan to a full recon-to-report penetration test.
A 12-step learning path. Follow it in order, or jump to what you need.
For security analysts, sysadmins, or developers ready to move from defense to offense, this is the hands-on, PTES-style path to becoming a working penetration tester. Plan on about 6 weeks at a few hours a week, moving from legal reconnaissance through scanning, web and API exploitation, credential attacks, and privilege escalation to a full engagement report. This path stays on offense: it skips the SOC-side detection and compliance work covered in the Cybersecurity Analyst path, and the developer-facing secure-coding lens covered in Web & Application Security. By the end you can scope and run an authorized penetration test, chain a web or API vulnerability into a working foothold, escalate that foothold to domain admin, and write up the findings in a report a client can act on.
Expected: basic networking (TCP/IP, DNS, common ports) and comfort with a Linux command line. Helpful but not required: Python or Bash scripting, and a general security background.
Lays out the legal boundaries, scope, and shared vocabulary (CVE, CVSS, ATT&CK) every later step assumes you already agreed to before touching a target.
Turns the scoped target from step one into a real attack surface, the subdomains, exposed services, and employee footprint that decide where scanning even starts.
Converts the domains and IPs recon surfaced into a live map of open ports and running services, the raw material every exploitation attempt in this path depends on.
You can scope a legal engagement and turn a domain name into a live map of open ports and services. Next up: turning that map into an actual way in.
Finish this section to unlock.
+100 XP
Names the vulnerability classes hiding behind the web ports step three's scan turned up, so you're hunting known patterns like broken access control and injection instead of guessing.
Hands you the SAST/DAST/fuzzing tooling that actually finds the OWASP categories from step four at scale, plus the bug-bounty workflow for practicing on real targets.
Applies the same broken-access-control thinking to the APIs behind every modern app, now the single largest slice of the attack surface you'll actually be paid to test.
Gives you the credential-access playbook, cracking, spraying, pass-the-hash, that turns the usernames and services steps two and three surfaced into an actual login.
This is where the login from step seven becomes real access; expect to come back to it constantly, since turning one compromised account into domain admin is what actually separates a pentester from a script runner.
You can chain a web or API flaw into a foothold, crack or spray your way to a login, and push that login all the way to domain admin, and a few minutes of due flashcards keeps the OWASP categories and Nmap flags from section one sharp while you build on them. Next up: picking a specialization and turning the whole chain into a report a client can act on.
Finish this section to unlock.
+100 XP
Take this if you're heading toward on-site or red-team engagements: wireless attacks like deauth and evil-twin open a foothold that step three's wired network scan never touches.
Grab this if cloud is in your engagement scope: the IAM and storage misconfigurations here are the cloud-side twin of the API flaws you chased in step six.
Worth it if you want the industry's most recognized proof of skill: it drills the exact recon-to-privesc chain from steps two through eight under a 24-hour exam clock.
Pulls recon, scanning, exploitation, and privilege escalation from every earlier step into the one deliverable that defines the job: a full engagement with a report a client can act on.
You can scope, recon, exploit, escalate, and report on a full penetration test end to end. This badge marks you ready to run an authorized engagement from first scan to final debrief.
Finish this section to unlock.
+100 XP
Finish every required step, at least 70% of them genuinely done (not skipped), to earn this badge and 500 XP.